nerdexam
EC-Council

312-50V13 · Question #295

Morris, a professional hacker, performed a vulnerability scan on a target organization by sniffing the traffic on the network lo identify the active systems, network services, applications, and…

The correct answer is B. Passive assessment. Passive Assessment Explained Why B is Correct: A passive assessment involves monitoring and analyzing network traffic without actively sending probes or interacting directly with target systems. Morris performed this by sniffing network traffic to identify active systems…

Submitted by ngozi_ng· Mar 6, 2026Vulnerability Analysis

Question

Morris, a professional hacker, performed a vulnerability scan on a target organization by sniffing the traffic on the network lo identify the active systems, network services, applications, and vulnerabilities. He also obtained the list of the users who are currently accessing the network. What is the type of vulnerability assessment that Morris performed on the target organization?

Options

  • Ainternal assessment
  • BPassive assessment
  • CExternal assessment
  • DCredentialed assessment

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    87% (47)
  • C
    4% (2)
  • D
    7% (4)

Explanation

Passive Assessment Explained

Why B is Correct: A passive assessment involves monitoring and analyzing network traffic without actively sending probes or interacting directly with target systems. Morris performed this by sniffing network traffic to identify active systems, services, applications, vulnerabilities, and logged-in users - a hallmark of passive techniques that observe rather than interrogate.

Why the Other Options Are Wrong:

  • A (Internal Assessment): This refers to assessments conducted from within the organization's network perimeter, focusing on insider threats - it's about location, not methodology.
  • C (External Assessment): This involves scanning from outside the network perimeter to simulate an external attacker - again, a location-based concept, not a traffic-sniffing technique.
  • D (Credentialed Assessment): This requires valid login credentials to perform in-depth scanning of systems - Morris used no such credentials; he simply observed traffic.

Memory Tip: Think of Passive = Eavesdropping - just like passively listening to a conversation without participating, a passive assessment listens to network traffic without actively probing or engaging targets. If you see "sniffing traffic" in an exam question, immediately think Passive Assessment.

Topics

#Vulnerability assessment#Passive assessment#Network sniffing#Reconnaissance

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice